zone-engine/workplans/ZONE-WP-0003-security-layer-model-alignment.md
tegwick acfd93fc86 feat: finish ZONE-WP-0003 Engine/PIP freeze and claim mapping
Declare the layer in layer.yaml, check it against INTENT.md, and fail
make check on a new Tooling client or HTTP decision surface. Record the
six statute §10 artifacts for the 2026-08-23 cut, name access-engine on
the README, and offer a non-schema PIP field mapping to Taxonomy.

Assistant: grok
Assistant-Session: 01a04ceb-0745-7ae1-9e26-0d10e5d52b8b
2026-08-29 12:49:24 +02:00

260 lines
11 KiB
Markdown
Raw Permalink Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

---
id: ZONE-WP-0003
type: workplan
title: "Declare Engine/PIP and freeze the offline zone-membership surface"
domain: infotech
repo: zone-engine
status: finished
owner: zone-engine
assignee: grok
lane: yellow
topic_slug: netkingdom
planning_priority: P1
created: "2026-08-29"
updated: "2026-08-29"
quality_dod: DoD-Ok
quality_dod_at: "2026-08-29"
quality_dod_by: grok
quality_dod_note: "layer.yaml agrees with INTENT.md; make check covers the freeze (no Tooling client, no decision surface); §10 artifacts and PIP claim mapping are cited; README uses the ruled PDP name; no live API was added."
origin: "history/2026-08-29-security-layer-model-scope-against-intent.md"
context_paths:
- "GOAL.md"
- "INTENT.md"
- "SCOPE.md"
- "README.md"
- "intakes/intakes.md"
- "history/2026-08-23-retain-reference-decision.md"
- "history/2026-08-29-security-layer-model-scope-against-intent.md"
quality_dor: DoR-Ok
quality_dor_at: "2026-08-29"
quality_dor_by: grok
quality_dor_note: "Gaps are evidenced against security-layer-model v0.7, companion v0.2, and the shipped offline resolver; owners, stop conditions, and the no-runtime freeze are explicit."
state_hub_workstream_id: "95573eaf-0b3f-5d48-af55-231f46d7295e"
---
# ZONE-WP-0003 — Declare Engine/PIP and freeze the offline zone-membership surface
## Goal
Make this repository a conforming Engine-layer PIP under NetKingdom Security
Layer Model v0.7 without reversing the 2026-08-23 no-runtime decision. Declare
the layer in a machine-readable form, close the declaration intake, record the
already-completed layer cut, and map current membership output onto the facts
a future request-claim must carry.
Source review: `history/2026-08-29-security-layer-model-scope-against-intent.md`.
Statute: `net-kingdom/canon/standards/security-layer-model_v0.7.md`.
Companion: `net-kingdom/SECURITY-COMPANION.md` v0.2.
`INTENT.md` already declares `layer: Engine` and `role: PIP` in this
repository's own voice. This workplan makes that declaration checkable and
closes the remaining documentary gaps. It does not add a live API.
## Why these gaps are the relevant ones
| Priority | Gap | Why address it here |
| --- | --- | --- |
| P0 | No `layer.yaml` or conformance check | Statute §11 is mechanical; a new Tooling client or decision surface would land as the small convenience §6 warns about |
| P0 | `ZONE-IN-0001` still open after the declaration | gate-house asked for our voice; §14 still counts us among the silent nine |
| P1 | Statute §10 artifacts for the 2026-08-23 cut are incomplete | The procedure was written from this case; the freeze is the checkable piece |
| P1 | `README.md` still names only `flex-auth` | Consumer-facing docs must use the ruled PDP name |
| P1 | Resolver output is membership, not a claim | Statute §18 wants claims; §17 forbids inventing the schema here |
A live Engine API, a PEP stance map, compiled stance, reef/zone composition,
and the `flex-auth` repository rename are intentionally excluded.
## Authority and dependencies
- **gate-house / net-kingdom** own the statute and the §4 catalog. This plan
declares into that catalog; it does not edit it.
- **`access-engine` (currently `flex-auth`)** owns the PDP, policy packages,
and the governed rename. This plan uses the ruled name in prose and leaves
fixture owner identities as `flex-auth` until that rename lands.
- **Taxonomy** owns the request-claim schema (statute §17, unassigned). This
plan offers a field mapping, not a schema.
- **zone-engine** owns the declaration, the conformance check, the freeze
record, and the PIP mapping note.
- **Operator action** is not required. No archive, rename, or service
deployment is in this plan.
## Boundaries
- Do not add an API, daemon, database, controller, scheduler, or reload path.
- Do not expose an authorization decision surface or cache a verdict.
- Do not compile stance into membership or change a live effect from a local
profile edit.
- Do not publish a PEP stance map; this repository is not PEP-shaped.
- Do not invent the estate request-claim schema.
- Do not map `reef-*` onto security zones.
- Do not treat observation-in-production or automatic containment as available.
- Do not fold `ZONE-WP-0001` or `ZONE-WP-0002` back open.
- Leave fixture `policy_owner` / source identities as the actual repository
names they pin.
## T01 - Machine-readable layer declaration and conformance check
```task
id: ZONE-WP-0003-T01
status: done
priority: high
state_hub_task_id: "ca687f30-2ad5-5243-8e48-efc34c78465c"
```
Add `layer.yaml` in the kings-guard no-contact shape, pointing at security
layer model v0.7:
- `layer: engine`
- `role: pip`
- `tooling_contacts: []`
- `non_tooling_clients` lists any State Hub / work-record client, recorded
as not-catalogued
- no `pep_stance` path
- catalog note: §4 Engine / PIP; offline reference conformance per the
2026-08-23 disposition
Add `tools/check_layer_conformance.py` and a unit test. The check must fail
if:
- `layer.yaml` is missing, unparseable, or disagrees with `INTENT.md`
frontmatter;
- a Tooling-layer client import appears under `tools/` (OpenBao/Vault,
cluster, direct datastore);
- a new HTTP authorization decision surface appears.
Wire it into `make check`. Review dates, if any, are reported, never used as
a calendar-day build failure.
**Done when:** `layer.yaml` is committed, agrees with `INTENT.md`, `make check`
covers it, and a reviewer can see there are no Tooling contacts, no PEP
claim, and no decision surface.
## T02 - Close ZONE-IN-0001 and notify gate-house
```task
id: ZONE-WP-0003-T02
status: done
priority: high
state_hub_task_id: "c0f726a6-def6-5318-8270-09c9de3e8678"
```
Close `ZONE-IN-0001` in `intakes/intakes.md` with outcome `absorbed` /
promoted to this workplan, recording that the proposed Engine layer is
assented in this repository's own voice and that the offline PIP form is the
catalogued surface, not a contest.
Notify `gate-house` (State Hub message or equivalent durable notice) that
zone-engine has declared Engine / PIP under v0.7 so statute §14 can stop
counting this repository among the undeclared nine.
**Done when:** the intake file is closed with a resolution that points at
`INTENT.md` and this workplan, and the notice to `gate-house` exists.
## T03 - Record the §10 artifacts for the 2026-08-23 layer cut
```task
id: ZONE-WP-0003-T03
status: done
priority: medium
state_hub_task_id: "828a4c67-9644-5b27-ac97-d79563848dfc"
```
Write a short retrospective under `history/` (or a `docs/` note cited from
`INTENT.md`) that gathers the six statute §10 artifacts for the already
completed cut:
| Artifact | Source |
| --- | --- |
| before/after `INTENT.md` | 2026-08-23 retain text vs 2026-08-29 declaration |
| client inventory | none against Tooling; offline Python tools only |
| gap inventory | none as §5.3 contacts; live Engine API is not a gap this repo currently owes |
| assent list | flex-auth / ops-warden adoption already evidenced; no new boundary moves |
| state-migration decision | `history/2026-08-23-retain-reference-decision.md` |
| permission freeze | no live API, no decision surface, no compiled stance until a later cut carries its own six artifacts |
**Done when:** a reviewer can find all six artifacts without reconstructing
them from workplan history, and `INTENT.md` or `SCOPE.md` cites the note.
## T04 - Align remaining consumer-facing naming
```task
id: ZONE-WP-0003-T04
status: done
priority: medium
state_hub_task_id: "bd4955b6-dfb8-59e5-be20-f4f8ab93ae8e"
```
Update `README.md` so a first-time reader sees Engine / PIP, offline
reference, and `access-engine` as the ruled PDP name (currently `flex-auth`).
Do not rewrite historical evidence, workplan files, or fixture owner
identities.
Confirm `GOAL.md` invariants already match; only patch if T01T03 drift them.
**Done when:** `README.md`, `INTENT.md`, `SCOPE.md`, and `GOAL.md` agree on
layer, role, and PDP name, and `git grep access-engine README.md INTENT.md
SCOPE.md GOAL.md` is the consumer-facing surface.
## T05 - PIP claim-boundary note, without a schema
```task
id: ZONE-WP-0003-T05
status: done
priority: medium
state_hub_task_id: "ee883d61-4d27-5223-826c-c37f66e3bcb4"
```
Write `docs/pip-claim-boundary.md` that:
1. lists the facts this PIP owns today (authoritative identity, declared and
effective zone, admission result and reason, membership revision, source
and source revision);
2. maps those fields onto what a future statute §17 request-claim must carry
(issuer, freshness, zone membership — not stance, not failure mode);
3. states that stance and failure mode remain owner policy and PEP
configuration, consumed by `access-engine` as a claim or a versioned rule
(statute §18);
4. marks the mapping as a contribution to Taxonomy, not a published schema;
5. forbids a competing claim dialect and forbids compiling those facts into
registry content that determines an outcome.
Offer the note to `gate-house` / `net-kingdom` and to `access-engine`. Do not
wait on their assent to keep the freeze.
**Done when:** the note is cited from `SCOPE.md`, tests still pass unchanged,
and no new wire format has shipped.
## Acceptance criteria
- [x] `layer.yaml` declares Engine / PIP, no Tooling contacts, no PEP map.
- [x] `make check` fails a new undeclared Tooling client or decision surface.
- [x] `ZONE-IN-0001` is closed on the own-voice declaration.
- [x] `gate-house` has been notified.
- [x] Statute §10 artifacts for the 2026-08-23 cut are gathered in one place.
- [x] Consumer-facing docs use `access-engine` as the ruled PDP name.
- [x] PIP facts are mapped for a future claim schema without shipping one.
- [x] No live API, daemon, decision surface, or compiled stance was added.
## Out of scope
- A zone-engine API, daemon, database, controller, scheduler, or synchronous
lookup.
- Publishing a PEP unreachable-engine stance map.
- Compiling stance into registry content or changing owner policy.
- Inventing or publishing the estate request-claim schema.
- Mapping Railiance reefs onto security zones.
- The `flex-auth``access-engine` repository rename.
- Promoting `security-zones_v0.1` out of `proposed`.
- Archiving or renaming this Forgejo repository.
- Estate-wide reference migration of unresolved catalog entries.
## Stop conditions
Stop and return to the relevant owner if implementation would require any of
the following:
- adding zone-engine to a live authorization or enforcement path;
- making a local profile authoritative over an owner policy package;
- inventing a claim schema and presenting it as estate canon;
- cataloguing this repository as PEP-shaped;
- reversing the 2026-08-23 retain / no-runtime decision without a new §10
layer-change record and assent from the repositories whose boundaries move.